GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,870 advisories
Filter by severity
Magento Business Logic Error vulnerability
Moderate
CVE-2025-24425
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Incorrect Authorization vulnerability
Moderate
CVE-2025-24421
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24417
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24412
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
High
CVE-2025-24411
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24413
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24415
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Information Exposure vulnerability
Moderate
CVE-2025-24408
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24416
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24410
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24414
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Mautic allows Relative Path Traversal in assets file upload
Moderate
CVE-2022-25773
was published
for
mautic/core
(Composer)
Feb 26, 2025
Mautic allows Improper Authorization in Reporting API
High
CVE-2024-47053
was published
for
mautic/core
(Composer)
Feb 26, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
Critical
CVE-2024-47051
was published
for
mautic/core
(Composer)
Feb 26, 2025
Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale
Moderate
CVE-2025-22145
was published
for
nesbot/carbon
(Composer)
Jan 8, 2025
MediaWiki UnlinkedWikibase Cross-site Scripting vulnerability
Moderate
CVE-2024-34500
was published
for
samwilson/unlinked-wikibase
(Composer)
May 5, 2024
Moodle allows teachers to evade trusttext config when restoring glossary entries
Low
CVE-2025-26532
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle allows reflected XSS via question bank filter
High
CVE-2025-26530
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has an IDOR in badges allows disabling of arbitrary badges
Low
CVE-2025-26531
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has a stored XSS in ddimageortext question type
Low
CVE-2025-26528
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has a stored XSS risk in admin live log
High
CVE-2025-26529
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has an arbitrary file read risk through pdfTeX
High
CVE-2025-26525
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle's feedback response viewing and deletions did not respect Separate Groups mode
Moderate
CVE-2025-26526
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle's non-searchable tags can still be discovered on the tag search page and in the tags block
Moderate
CVE-2025-26527
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Leantime allows Cross-Site Scripting (XSS)
Low
GHSA-f679-254h-qhvj
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
ProTip!
Advisories are also available from the
GraphQL API